08-02-13 | Blog Post

Ensuring Cloud Vendor Security Transparency in the Age of Data Breaches

Blog Posts

Gartner recently released recommendations for gaining transparency into cloud software as a service (SaaS) contracts – including emphasis on annual security audits and certification by a third party to verify a cloud vendor’s operating/product security.

Gartner also recommends that contracts allow for an option to terminate the agreement in the event of a security breach if the provider fails on any material measure. Gartner’s report, Cloud Contracts Need Security Service Levels to Better Manage Risk reveals that 80 percent of IT procurement professionals will remain dissatisfied with SaaS contract language and protections that relate to security over the next two years.

“We continue to see frustration among cloud services users over the form and degree of transparency they are able to obtain from prospective and current service providers,” said Alexa Bona, vice president and analyst at Gartner.

So how can you maintain complete transparency into your cloud service provider’s ability to provide ongoing secure services? The following is relevant to cloud infrastructure as a service (IaaS) providers that may offer services to other software as a service (SaaS) providers:

  • Check compliance audit reports. The list of security audits that should be conducted by an independent third-party auditor at least annually is a long one – it just depends what you’re looking for and what industry you’re in. Take this Data Center Audits Cheat Sheet with you to your data center visit.
  • Visit the actual data center. Verify your cloud service provider owns and operates their facilities, and then schedule a tour to check out their physical and technical security. Talk to their staff and ensure they’ve been trained to handle sensitive data, as well as their policies around access.
  • Compare industry compliance requirements with their offering.  Knowing who’s responsible for what clears up any gaps in your overall security, and clarifying what they offer and don’t also gives you insight into the scope of their services.
  • Find out what their breach notification policies are. Ask if the clause includes a standard notification policy if they discover a breach, and what the procedure involves after the event. Get your team involved to manage their end and ensure contacts are identified.

Gaining transparency into your cloud provider’s environment may take more upfront work on your organization’s part, but it could be worth it in the end – the Ponemon Institute revealed that the cost of a data breach is rising across the globe in 2013 Cost of Data Breach Study: Global Analysis (PDF).

Related Articles:
Enterprise Cloud Infrastructure as a Service (IaaS): Security, Reliability & Availability Desired
According to a recent survey by IT research firm Neovise as reported by CIOInsight.com of over 800 IT decision-makers in the U.S., enterprise cloud infrastructure as a service (IaaS) is the most widely adopted form of cloud computing. Thirty-seven percent … Continue reading →

Securing Regulated Data with a Private Cloud Infrastructure
Dr. Larry Ponemon, chairman and founder of the Ponemon Institute described how the shift of the attack surface from the mobile device is moving to unsecure places in the cloud environment with unsecure data, as reported by HealthITSecurity.com. More specifically, … Continue reading →

References:
Gartner Says Cloud Contracts Need More Transparency to Improve Risk Management

Overwhelmed by cloud chaos?
We’re cloud experts, so you don’t have to be.

© 2024 OTAVA® All Rights Reserved